Acronis True Image fails to update itself securely

Discussion in 'other security issues & news' started by ronjor, Jun 19, 2017.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,883
    Location:
    Texas
  2. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Geesh. And they sell a version that is supposed to help you with security.
     
  3. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,653
    Thanks Ron.

    I don't know whether you all noticed that this vulnerability article was written by the same person who wrote the recent vulnerability article about Samsung Magician (post by Ron here): Will Dormann of the CERT/CC.
    Now those two reported vulnerabilities are not the same. But I hope that Will Dormann will continue to look at more programs and how secure they update themselves. I could think of some...
     
  4. eturtseva

    eturtseva Registered Member

    Joined:
    Jun 21, 2017
    Posts:
    1
    Location:
    Boston
    Hi all,
    My name is Katya, VP of communications at Acronis.

    Here is our official comment about it:

    Acronis is aware of a minor security issue related to Acronis True Image (versions 2017 Build 8053 and earlier) that was reported by our colleagues at CERT Coordination Center (CERT/CC) at Carnegie Mellon University's Software Engineering Institute.

    We immediately fixed the vulnerability, prepared a patch for our newest update, and are currently notifying users of the issue.

    While the threat to users is considered low-risk since multiple, rare occurrences would need to happen in order for someone to exploit the vulnerability, we are urging all Acronis True Image customers to apply the patch by opening the application and selecting “Check for Updates.”

    Acronis takes data protection very seriously, which is why we have acted so quickly to respond to this threat. We will examine this incident further to ensure no similar vulnerabilities exist in our products.
     
  5. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Has Acronis patched the vulnerability in the pipes upstream of the client so that downloading the patch will be done through a newly secured line or is installation of the patch required to fully secure the internal download process? If the latter, hawki questions the wisdom of encouraging all to download the patch through the internal update process which is what your statement seems to imply.

    Sorry, but hawki is not what one would consider an Acronis fanboi atm:

    https://www.wilderssecurity.com/threads/bork-tuesday-any-problems-yet.370217/page-126#post-2686661
     
    Last edited: Jun 21, 2017
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.